Name | CVE-2007-3215 |
Description | PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-1315-1 |
Debian Bugs | 429179, 429190, 429191, 429192, 429193, 429194, 429195, 429196, 429197, 504253, 504255 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
libphp-phpmailer (PTS) | bullseye | 6.2.0-2 | fixed |
bookworm | 6.6.3-1 | fixed | |
sid, trixie | 6.9.1-1 | fixed | |
wordpress (PTS) | bullseye (security), bullseye | 5.7.11+dfsg1-0+deb11u1 | fixed |
bookworm, bookworm (security) | 6.1.6+dfsg1-0+deb12u1 | fixed | |
sid, trixie | 6.6.1+dfsg1-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
egroupware | source | (unstable) | (not affected) | |||
flyspray | source | sarge | (not affected) | |||
flyspray | source | etch | (not affected) | |||
flyspray | source | (unstable) | 0.9.8-12 | 429191, 429195 | ||
glpi | source | etch | (not affected) | |||
glpi | source | (unstable) | 0.68.3.2-1 | 429192 | ||
ipplan | source | (unstable) | 4.85-2 | 429193 | ||
knowledgeroot | source | etch | (not affected) | |||
knowledgeroot | source | (unstable) | 0.9.8.2-2 | 429196 | ||
libphp-phpmailer | source | etch | 1.73-2etch1 | DSA-1315-1 | ||
libphp-phpmailer | source | (unstable) | 1.73-4 | high | 429179 | |
mahara | source | lenny | 1.0.4-3 | |||
mahara | source | (unstable) | 1.0.5-2 | 504253 | ||
moodle | source | (unstable) | 1.8.2-2 | 429190 | ||
owl-dms | source | etch | (not affected) | |||
owl-dms | source | (unstable) | 0.94-2 | 429197 | ||
phpgroupware | source | etch | (not affected) | |||
phpgroupware | source | (unstable) | 0.9.16.012+dfsg-9 | medium | 504255 | |
wordpress | source | etch | (not affected) | |||
wordpress | source | (unstable) | 2.2.1-1 | 429194 |
[etch] - flyspray <not-affected> (Vulnerable code not)
[sarge] - flyspray <not-affected> (Vulnerable code not included)
[etch] - knowledgeroot <not-affected> (Vulnerable code not used)
[etch] - owl-dms <not-affected> (Vulnerable code not used)
[etch] - glpi <not-affected> (Vulnerable code not used)
[etch] - wordpress <not-affected> (Vulnerable code not present)
[etch] - phpgroupware <not-affected> (bug #504255; Vulnerable code not used)
- egroupware <not-affected> (bug #504283; Vulnerable code not used)